Skip to content

Is it normal for my upstream's upstream to email me directly?

Networking by Carl 24 replies 2.6K views
#1

Got an email yesterday from someone claiming to be "upstream operations" for my provider. Not my provider—my provider's provider. They said they got an abuse complaint about "scanning activity" from my /24 and wanted "to discuss before escalating to NOC."

I lease a half-rack at a regional datacenter, single 10G drop, paying for 2kW. Never had direct contact with anyone above my immediate colo. The email came from a hostnamed address that doesn't resolve to anything I can find in WHOIS.

Is this normal? Feels like a social engineering attempt but the details were partially correct—wrong date for the alleged scan, right IP block.

visit twice: install and decom
#2

Not normal. Legitimate Tier 2 contact goes through your provider, not around them. Bypass chain of custody suggests either:
- compromised ticketing system at your colo
- WHOIS scrape with poor role account parsing
- prep for targeted followup (DDoS extortion, common after "abuse" softening)

Check headers for originating netblock. If outside your colo's ASN, likely spoofed. If same ASN, possible but still unusual. Anycast vs scrubbing context irrelevant here unless they mention mitigation services next.

mitigated 800Gbps before breakfast
4 #3

> Check headers for originating netblock

Did that first thing. SPF passed but the return path domain was registered three weeks ago. My actual colo still has not answered my ticket from yesterday so I am leaning toward spoofed.

#4

Three weeks old domain is the smoking gun. Real upstream ops use domains registered before you were born, or at least before your current contract started. I've had two of these in the last year—both led to extortion attempts a week later. "Pay us in BTC or we escalate to your upstream." Your colo's silence is another red flag. Twenty years and I still can't get some NOCs to answer tickets inside 48 hours.

IPv4, IRC, and irssi — fight me
#5

SPF pass on a fresh domain is trivial. Register domain, publish permissive SPF, send from any host that matches. The hard part is the IP block knowledge. That suggests either:

  • Public BGP looking glass query
  • Compromised account at your colo with customer data access
  • Prior reconnaissance on your /24 (port scan, service banners)

The wrong date is interesting. Either sloppy automation or deliberate misdirection to make you correct them, establishing rapport.

mitigated 800Gbps before breakfast
#6

My colo finally answered. They have no record of any abuse ticket or upstream contact. They also confirmed they do not use the domain that emailed me. So spoofed, but where did they get the /24? I only announced it six months ago.

6 #7

Hospital NOC here—six months is plenty. RIPE whois for your range, cross-reference with peeringDB, maybe you listed a website or contact in some RIR object? We get scraped constantly. The "wrong date" thing happened to us too, turned out to be a template reuse from a previous campaign.

#8

In Poland we see this with hosting resellers. Upstream "contacts" customer directly to sell mitigation or "premium abuse handling." Sometimes the upstream is real but the contact is a sales guy breaking protocol. Check if the domain registrant matches any known protection racket.

#9

> premium abuse handling

That's a new one. Back in my day they just threatened to null-route you until you bought "clean pipe" from their buddy's shell company.

IPv4, IRC, and irssi — fight me
#10

Estonia has similar. The "escalation" language is key—creates urgency, bypasses rational checks. Real NOC escalation is automated and silent. You get null-routed, then you find out, then you call them. No courtesy emails.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft